Security issues harm YouTube

Aug 28, 2007 12:33 GMT  ·  By

Google's video service YouTube is more and more affected by security problems especially because the online video sharing platform is very popular and has millions of users every day. Because of that, the hackers and the attackers are turning to YouTube in order to find vulnerable victims to exploit their computers. Today, the security companies discovered a dangerous worm that uses the YouTube brand to trick users to download and run it. Here's the full coverage on this threat. Basically, the attacker sends numerous malicious emails to the potential victims, encouraging them to click on a link to download the video. Obviously, the link was redirecting the user to a dangerous website that tried to infect his computer.

But this is not the first time when YouTube is affected by a dangerous threat that can harm the users' computers. In the past, it was reported that other attackers were trying to use the YouTube popularity in order to trick the naive consumers to click on a link that actually attempted to infect their computers. It is somehow similar with today's worm so you should better avoid clicking on links coming from untrusted or unknown source.

"The gang behind these attacks are amongst the most professional we have ever seen - spewing out new variants of their code with multiple disguises in their attempt to infect as many PCs as possible," said Graham Cluley, senior technology consultant for Sophos. "Clicking on the links in the email doesn't take you to YouTube's real website, but the IP address of a compromised PC. If infected, victims' computers can be used by hackers to steal personal information, spam out malware and junk email, or launch distributed denial of service attacks against innocent parties."

Just like a simple trick to avoid getting infected: move your mouse cursor over the link without clicking on it (!!!) and look at the status bar of your browser. It will show you the correct destination of the link. Beware, this can be also modified by the attackers!